Symantec: GodDamn Ransomware Attack Uses PsExec Lateral Movement and NirSoft Toolkit for Credential Theft

Symantec: GodDamn Ransomware Attack Uses PsExec Lateral Movement and NirSoft Toolkit for Credential Theft

GodDamn Ransomware: A Rebranded Threat with Kernel-Level Evasion Tactics

A recent ransomware campaign attributed to the GodDamn strain has been identified as a rebrand of the long-running Hyadina ransomware family, previously known as Monster (2022) and Beast (2024). The attack, observed in late May and early June 2026, demonstrates refined tactics, including kernel-level defense subversion and systematic credential harvesting, allowing threat actors to evade detection and move laterally within compromised networks.

The intrusion began with AnyDesk deployed from an unusual location the victim’s Music folder indicating manual installation by an operator with prior access. The remote-access tool was configured for unattended access, suppressing consent prompts and establishing persistence via registered services to survive reboots. This approach enabled stealthy, interactive control while minimizing behaviors that could trigger security alerts.

Credential theft was a key phase of the attack. Investigators discovered a staged toolkit under a user profile, including Mimikatz and 14 NirSoft utilities such as WebBrowserPassView, ChromePass, PasswordFox, and WirelessKeyView alongside Netscan for host discovery. This suite targeted browsers, email clients, VNC credentials, Wi-Fi profiles, and cached domain credentials, facilitating rapid lateral movement using stolen accounts.

Lateral movement was executed via PsExec, with all malicious commands routed through psexesvc.exe, services.exe, and wininit.exe. Attackers performed basic reconnaissance (e.g., ipconfig, tasklist), mounted administrative shares, and installed AnyDesk on additional hosts to create a resilient remote-access infrastructure. A PowerShell installer accelerated deployment across at least 10 hosts in the observed environment.

A particularly dangerous aspect of the campaign was the use of PoisonX, a signed malicious kernel driver disguised as a Symantec binary. The driver, signed under "Microsoft Windows Hardware Compatibility Publisher," could terminate security processes and remove user-mode hooks, effectively blinding endpoint defenses. Unlike typical BYOVD (bring-your-own-vulnerable-driver) attacks, PoisonX was a maliciously signed driver, granting attackers an unusually powerful evasion capability. The driver had been previously documented in early 2026 for similar CrowdStrike-disabling behavior.

After disabling defenses including Defender real-time monitoring and harvesting credentials, the attackers maintained a dwell period before deploying encryption. GodDamn ransomware samples were found in user profile directories, with encrypted files typically receiving a .God8Damn extension. However, in the incident investigated by Symantec, the attackers used the victim organization’s name as the extension, a rare tactic that may aid future attribution.

The attack’s timeline, toolset, and techniques align with Hyadina’s historical operations, including the persistent use of NirSoft tools, AnyDesk, and rebranded ransomware variants. The group’s evolution from Monster (2022) to Beast (2024) to GodDamn (2026) reflects a pattern of refining encryption methods and targeting strategies while maintaining core operational playbooks.

Source: https://gbhackers.com/goddamn-ransomware-attack/

Symantec cybersecurity rating report: https://www.rankiteo.com/company/symantec

"id": "SYM1783607031",
"linkid": "symantec",
"type": "Ransomware",
"date": "5/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'type': 'Organization'}],
 'attack_vector': 'Manual deployment via remote-access tool (AnyDesk)',
 'data_breach': {'data_encryption': True,
                 'personally_identifiable_information': True,
                 'sensitivity_of_data': 'High (personally identifiable '
                                        'information, payment information)',
                 'type_of_data_compromised': ['Browser credentials',
                                              'Email client credentials',
                                              'VNC credentials',
                                              'Wi-Fi profiles',
                                              'Cached domain credentials']},
 'date_detected': '2026-05',
 'description': 'A recent ransomware campaign attributed to the GodDamn '
                'strain, a rebrand of the Hyadina ransomware family, '
                'demonstrated refined tactics including kernel-level defense '
                'subversion and systematic credential harvesting. The attack '
                'involved manual deployment of AnyDesk, credential theft using '
                'Mimikatz and NirSoft utilities, lateral movement via PsExec, '
                'and the use of a signed malicious kernel driver (PoisonX) to '
                'disable security defenses before deploying ransomware with a '
                'custom file extension.',
 'impact': {'data_compromised': True,
            'identity_theft_risk': True,
            'operational_impact': 'Lateral movement, credential harvesting, '
                                  'and security defense subversion',
            'payment_information_risk': True,
            'systems_affected': 'At least 10 hosts'},
 'initial_access_broker': {'backdoors_established': 'Unattended AnyDesk access '
                                                    'with persistence via '
                                                    'registered services',
                           'entry_point': 'AnyDesk deployed from Music folder '
                                          '(manual installation)'},
 'investigation_status': 'Ongoing',
 'motivation': 'Financial gain (ransomware extortion)',
 'post_incident_analysis': {'root_causes': ['Manual deployment of AnyDesk',
                                            'Credential harvesting via '
                                            'Mimikatz and NirSoft utilities',
                                            'Use of signed malicious kernel '
                                            'driver (PoisonX) to disable '
                                            'security defenses']},
 'ransomware': {'data_encryption': True,
                'ransomware_strain': 'GodDamn (rebrand of '
                                     'Hyadina/Monster/Beast)'},
 'references': [{'source': 'Symantec'}],
 'response': {'third_party_assistance': 'Symantec (investigation)'},
 'threat_actor': 'Hyadina ransomware group (rebranded as GodDamn)',
 'title': 'GodDamn Ransomware Attack with Kernel-Level Evasion Tactics',
 'type': 'Ransomware'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.